USN-7082-1: libheif vulnerability
Published Oct 23, 2024
·Updated
Gerrard Tai discovered that libheif did not properly validate certain images, leading to out-of-bounds read and write vulnerability. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service or to obtain sensitive information.
Affected Software
2 affected componentsFixes available
All of the following
ubuntu/libheif1<1.17.6-1ubuntu4.1
1.17.6-1ubuntu4.1
Ubuntu Ubuntu=24.04
Event History
Oct 23, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7082-1?
USN-7082-1 is categorized as a high severity vulnerability due to its potential for causing denial of service.
2
How do I fix USN-7082-1?
To fix USN-7082-1, upgrade the libheif package to version 1.17.6-1ubuntu4.1 or later.
3
What does USN-7082-1 affect?
USN-7082-1 affects the libheif package used in Ubuntu 24.04.
4
What type of vulnerability is USN-7082-1?
USN-7082-1 is an out-of-bounds read and write vulnerability.
5
Who discovered USN-7082-1?
USN-7082-1 was discovered by researcher Gerrard Tai.